How the scam operates.
Situs ini menampilkan dirinya sebagai antarmuka wallet Ethereum yang sah, meminjam nama dan reputasi yang tersirat dari layanan wallet yang sudah mapan. Permukaan operasional, nama domain, kemungkinan desain visual, serta bahasa yang dihadapkan kepada pengguna, dirancang agar tidak dapat dibedakan secara sekilas dari platform aslinya. Sasarannya adalah pengguna Ethereum yang mencari akses wallet, khususnya mereka yang tiba melalui mesin pencari, tautan media sosial, atau URL yang diteruskan, alih-alih melalui bookmark yang diketik sendiri.
Mekanismenya mengikuti model pemanenan kredensial standar yang lazim pada operasi phishing wallet. Pengunjung diminta memasukkan seed phrase, private key, atau berkas keystore dengan dalih masuk atau memulihkan akses ke sebuah akun. Operator menangkap kredensial ini di sisi server pada saat dimasukkan. Karena private key Ethereum memberikan kendali tanpa syarat dan tidak dapat dibatalkan atas dana yang terkait, satu kali penangkapan yang berhasil sudah cukup untuk menguras seluruh aset yang tersimpan dalam wallet yang menjadi sasaran, tanpa memerlukan interaksi lebih lanjut dari korban.
Kegagalan biasanya baru terlihat setelah kredensial sudah terlanjur dikirimkan. Pengguna menyadari bahwa antarmuka menampilkan pesan kesalahan, mengalihkan secara tak terduga, atau tampak berfungsi normal sementara sebuah proses paralel secara diam-diam menguras wallet. Pada saat ketidaksesuaian itu mulai diselidiki, operator telah memindahkan dana melalui satu atau beberapa alamat perantara, sehingga penelusuran on-chain menjadi sulit tanpa perangkat khusus. Tidak ada mekanisme pemulihan atau sengketa di dalam platform, karena memang tidak pernah dimaksudkan untuk ada.
Red flags we documented.
- 01TLD substitution as impersonation techniqueThe domain replicates the name of a recognised Ethereum wallet service while substituting a different top-level domain. This pattern, known as TLD spoofing, is a deliberate attempt to exploit typographical error and user inattention. Legitimate wallet providers do not operate across multiple conflicting TLDs.
- 02.su TLD registration patternThe .su ccTLD (administered for the former Soviet Union) remains operational and is disproportionately represented in fraud and phishing infrastructure due to minimal registration oversight and enforcement cooperation. Its use here provides no legitimate geographic or operational justification.
- 03CryptoScamDB blacklist confirmationThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained dataset used by wallet software, browser extensions, and security researchers to block known malicious addresses. Inclusion reflects documented community reports, not automated heuristics alone.
- 04Private-key harvest, irreversible loss exposureWallet phishing operations targeting seed phrases or private keys expose victims to total, permanent asset loss. Unlike payment card fraud, there is no chargeback mechanism and no custodial institution to contest with. Any platform requesting a private key or seed phrase outside of a locally-running, verifiable application should be treated as hostile.
- 05Absence of verifiable operational historyOperations of this type typically lack any auditable history, no company registration, no named team, no published security disclosures, and no track record predating the fraud campaign. The use of an impersonation domain further forecloses any legitimate identity claim the operator might otherwise make.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.